<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I break events within events . in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489236#M194044</link>
    <description>&lt;P&gt;In props.conf&lt;/P&gt;

&lt;P&gt;[your_sourcetype]&lt;BR /&gt;
LINE_BREAKER = ^()\w{3}\s\d\d|Scope Id&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:49:30 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2020-09-30T03:49:30Z</dc:date>
    <item>
      <title>How can I break events within events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489234#M194042</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I have middleware .out file to be monitored with Splunk.&lt;BR /&gt;The events are breaking with respect to the time stamps as below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1/16/20&lt;BR /&gt;12:27:17.553 PM &lt;BR /&gt;Jan 16, 2020 1:57:17,553 AM EST Warning Socket BEA-000449bClosing the socket, as no data read from it on ,322 during the configured idle timeout of 5 seconds.&lt;/P&gt;
&lt;P&gt;1/16/20&lt;BR /&gt;12:24:17.274 PM &lt;BR /&gt;Jan 16, 2020 1:54:17,274 AM EST Error oracle.soa.management.internal.ejb.impl.FacadeFinderBeanImp BEA-000000 No Facade Fault Recovery Service found for Engine type : service&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But i have an event in this log file which is breaking based on time stamp but single event isgoing beyond 800 1000lines . sample event below&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Jan 16, 2020 1:54:05,062 AM EST Error oracle.soa.bpel.engine.dispatch BEA-00000 Transaction rolledback, Transaction key = Name=[EJB &lt;BR /&gt;** Cikey: 100174&lt;BR /&gt;** ComponentDN: default/CommsProcessFulfillmentOrderBillingAccountListEBF!1.0*soa_50970aa3-f91e-430a-83db-70b3c1beafd9/CommsProcessFulfillmentOrderBillingAccountListEBF&lt;BR /&gt;** FlowId: 100048&lt;/P&gt;
&lt;H2&gt;** Set of Audit Events in currently rolledback transaction:&lt;/H2&gt;
&lt;P&gt;** Scope Id: 0&lt;BR /&gt;** Audit Event Date: Thu, 16 Jan 2020 01:54:04.300 EST&lt;BR /&gt;** Audit Message: New instance of BPEL process "1.0" initiated (# "CommsProcessFulfillmentOrderBillingAccountListEBF").&lt;/P&gt;
&lt;H2&gt;** Audit Detail: null&lt;/H2&gt;
&lt;P&gt;** Scope Id: BpSeq13.3&lt;BR /&gt;** Audit Event Date: Thu, 16 Jan 2020 01:54:04.301 EST&lt;BR /&gt;** Audit Message: Received "initiate" call from partner "client"&lt;BR /&gt;** Audit Detail: &lt;BR /&gt;CommsProcessFulfillmentOrderBillingAccountListReqMsg part name="ProcessFulfillmentOrderBillingAccountListEBM" xmlns:xsi="&lt;A href="http://www.w3.org/2001/XMLSchema-instance%22bProcessFulfillmentOrderBillingAccountListEBM" target="_blank" rel="noopener"&gt;http://www.w3.org/2001/XMLSchema-instance"bProcessFulfillmentOrderBillingAccountListEBM&lt;/A&gt; &lt;BR /&gt;** Audit Event Attributes: &lt;BR /&gt;** wikey: 100174-BpRcv0-BpSeq13.3-1&lt;BR /&gt;** label: receiveInput&lt;/P&gt;
&lt;H2&gt;** state: 5&lt;/H2&gt;
&lt;P&gt;** Scope Id: BpSeq13.3&lt;BR /&gt;** Audit Event Date: Thu, 16 Jan 2020 01:54:04.302 EST&lt;BR /&gt;** Audit Message: bpelx:exec executed&lt;BR /&gt;** Audit Detail: null&lt;BR /&gt;** Audit Event Attributes: &lt;BR /&gt;** wikey: 100174-BxExe0-BpSeq13.3-2&lt;BR /&gt;** label: Set_Title&lt;BR /&gt;** state: 5&lt;/P&gt;
&lt;P&gt;This event is more than 1000lines with lot of scope ID paragraph and I get a &lt;STRONG&gt;Show all 800lines&lt;/STRONG&gt; message , and when I expand the Splunk goes into hung state.&lt;BR /&gt;Though i can use &lt;STRONG&gt;Truncate&lt;/STRONG&gt; and &lt;STRONG&gt;max_events&lt;/STRONG&gt; value in props , how can i handle or break one big event with more than 800 lines based on the &lt;STRONG&gt;ScopeID&lt;/STRONG&gt; and also keep other events breaking based on timestamp as well .&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 14:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489234#M194042</guid>
      <dc:creator>Sujithkumarkb</dc:creator>
      <dc:date>2022-04-25T14:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break events within events .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489235#M194043</link>
      <description>&lt;P&gt;Try creating a field extraction on the UI with regex.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 21:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489235#M194043</guid>
      <dc:creator>vsai0718</dc:creator>
      <dc:date>2020-01-27T21:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break events within events .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489236#M194044</link>
      <description>&lt;P&gt;In props.conf&lt;/P&gt;

&lt;P&gt;[your_sourcetype]&lt;BR /&gt;
LINE_BREAKER = ^()\w{3}\s\d\d|Scope Id&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/489236#M194044</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-30T03:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break events within events .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/595190#M207129</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Wow, thanks for this thread. I didn't even think about splitting events within events. I'm still trying to figure out the Splunk search language, and I don't always get what I want the first time. I hope I won't bother anyone with my comment if I use it to "bookmark" the topic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 12:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/595190#M207129</guid>
      <dc:creator>lernauti</dc:creator>
      <dc:date>2022-04-25T12:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break events within events .</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/595382#M207214</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Wow, thanks for this thread. I didn't even think about splitting events within events. I'm still trying to figure out the Splunk search language, and I don't always get what I want the first time. I hope I won't bother anyone with my comment if I use it to "bookmark" the topic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I prefer to appear in all thematic forums and ask thousands of stupid questions to everyone. This is how I prevent possible errors, and it's better than carrying the hard drive to &lt;A href="https://www.salvagedata.com/hard-drive-recovery/" target="_self"&gt;the file recovery procedure&lt;/A&gt; later due to a series of wrong actions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 11:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-events-within-events/m-p/595382#M207214</guid>
      <dc:creator>lernauti</dc:creator>
      <dc:date>2022-04-26T11:06:46Z</dc:date>
    </item>
  </channel>
</rss>

